[RHSA-2020:0111] firefox security update
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
This update upgrades Firefox to version 68.4.1 ESR.
Security Fix(es):
Mozilla: IonMonkey type confusion with StoreElementHole and FallibleStoreElement (CVE-2019-17026)
Mozilla: Bypass of @namespace CSS sanitization during pasting (CVE-2019-17016)
Mozilla: Type Confusion in XPCVariant.cpp (CVE-2019-17017)
Mozilla: Memory safety bugs fixed in Firefox 72 and Firefox ESR 68.4 (CVE-2019-17024)
Mozilla: CSS sanitization does not escape HTML tags (CVE-2019-17022)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Package | Affected Version |
---|---|
pkg:rpm/redhat/firefox?arch=x86_64&distro=redhat-8.1 | < 68.4.1-1.el8_1 |
pkg:rpm/redhat/firefox?arch=s390x&distro=redhat-8.1 | < 68.4.1-1.el8_1 |
pkg:rpm/redhat/firefox?arch=ppc64le&distro=redhat-8.1 | < 68.4.1-1.el8_1 |
pkg:rpm/redhat/firefox?arch=aarch64&distro=redhat-8.1 | < 68.4.1-1.el8_1 |
- ID
- RHSA-2020:0111
- Severity
- critical
- URL
- https://access.redhat.com/errata/RHSA-2020:0111
- Published
-
2020-01-14T00:00:00
(4 years ago) - Modified
-
2020-01-14T00:00:00
(4 years ago) - Rights
- Copyright 2020 Red Hat, Inc.
- Other Advisories
-
- ALAS2-2020-1393
- ALPINE:CVE-2019-17016
- ALPINE:CVE-2019-17017
- ALPINE:CVE-2019-17022
- ALPINE:CVE-2019-17024
- ALPINE:CVE-2019-17026
- ASA-202001-1
- ASA-202001-3
- ASA-202001-4
- CISA-2021:1103
- DSA-4600-1
- DSA-4603-1
- ELSA-2020-0085
- ELSA-2020-0086
- ELSA-2020-0111
- ELSA-2020-0120
- ELSA-2020-0123
- ELSA-2020-0127
- GLSA-202003-02
- MFSA-2020-01
- MFSA-2020-02
- MFSA-2020-03
- MFSA-2020-04
- openSUSE-SU-2020:0060-1
- openSUSE-SU-2020:0094-1
- RHSA-2020:0085
- RHSA-2020:0086
- RHSA-2020:0120
- RHSA-2020:0123
- RHSA-2020:0127
- SSA:2020-010-01
- SUSE-SU-2020:0068-1
- SUSE-SU-2020:0078-1
- SUSE-SU-2020:0142-1
- USN-4234-1
- USN-4241-1
- USN-4335-1
Source | # ID | Name | URL |
---|---|---|---|
Bugzilla | 1788723 | https://bugzilla.redhat.com/1788723 | |
Bugzilla | 1788724 | https://bugzilla.redhat.com/1788724 | |
Bugzilla | 1788726 | https://bugzilla.redhat.com/1788726 | |
Bugzilla | 1788727 | https://bugzilla.redhat.com/1788727 | |
Bugzilla | 1789214 | https://bugzilla.redhat.com/1789214 | |
RHSA | RHSA-2020:0111 | https://access.redhat.com/errata/RHSA-2020:0111 | |
CVE | CVE-2019-17016 | https://access.redhat.com/security/cve/CVE-2019-17016 | |
CVE | CVE-2019-17017 | https://access.redhat.com/security/cve/CVE-2019-17017 | |
CVE | CVE-2019-17022 | https://access.redhat.com/security/cve/CVE-2019-17022 | |
CVE | CVE-2019-17024 | https://access.redhat.com/security/cve/CVE-2019-17024 | |
CVE | CVE-2019-17026 | https://access.redhat.com/security/cve/CVE-2019-17026 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/redhat/firefox?arch=x86_64&distro=redhat-8.1 | redhat | firefox | < 68.4.1-1.el8_1 | redhat-8.1 | x86_64 | |
Affected | pkg:rpm/redhat/firefox?arch=s390x&distro=redhat-8.1 | redhat | firefox | < 68.4.1-1.el8_1 | redhat-8.1 | s390x | |
Affected | pkg:rpm/redhat/firefox?arch=ppc64le&distro=redhat-8.1 | redhat | firefox | < 68.4.1-1.el8_1 | redhat-8.1 | ppc64le | |
Affected | pkg:rpm/redhat/firefox?arch=aarch64&distro=redhat-8.1 | redhat | firefox | < 68.4.1-1.el8_1 | redhat-8.1 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |